Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
Security research at Nokia Deepfield (he/they).
EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
Posts
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
New report from our ERT: #Maskify.
The operator built what a Series A deck would call "decentralized edge infrastructure": ENS for service discovery, IPFS for binary distribution, a custom P2P mesh network, QUIC transport.
In practice it is a DDoS botnet running on Android TV boxes that did not opt in.
https://github.com/deepfield/public-research/blob/main/maskify/report.md
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
When a botnet operator names their payload after your team, you check the diff.
libcyn.so → deepfield.so
Custom cipher → wolfSSL TLS 1.3 (same stack as earlier Kimwolf)
C2 domains, floods, targets: all unchanged.
9a28696774d9ef6754540633daeef668767df5efa1804138abd35e1a6b31523e
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
The backstory of #Kimwolf, from our initial sightings early last year to how @synthient@cyberplace.social discovered the vuln that made that botnet possible.
https://www.wsj.com/tech/kimwolf-hack-residential-proxy-networks-a712ab59?st=3eNTjx
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
New, from our @deepfield@infosec.exchange ERT: found a new botnet dressing its C2 traffic as camera management.
#Drifter names its domains after Hikvision products, blending with surveillance traffic on the same VLAN as the Android TV boxes it infects. DNS queries go through an Australian resolver, which somewhat undermines the cover if your bot is in São Paulo.
71 KB binary, already linked to attacks exceeding 2 Tbps from 80k sources. At least six operators are now competing for the same devices.
https://github.com/deepfield/public-research/blob/main/drifter/report.md
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
Other than publishing these botnet reports I’m enjoying my week off 🤣
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
RE: @deepfield@infosec.exchange
The operator built triple-layer crypto, fast-flux DNS across 30+ ASes, biweekly C2 rotation — then shipped an unstripped debug build on port 8090, a couple of ports over from production. 300+ symbols, project name, internal module names, all right there in readelf.
Anyway here's the full writeup.
https://github.com/deepfield/public-research/blob/main/jackskid/report.md
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
New, from our ERT: #CECbot, an Android TV botnet and the first malware we're aware of that exploits HDMI-CEC.
It puts the TV to sleep so you don't notice the box behind it is running DDoS and residential proxy traffic. Curve25519/ChaCha20 crypto, 9 persistence layers, and... LAN mapping.
Successor to a Mirai fork, shares not much but the C2 server.
https://github.com/deepfield/public-research/blob/main/cecbot/report.md
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
One custom RC4 seed led us to four botnets, five C2 channels, and a developer who shipped their Windows username and Cursor IDE logs with their malware.
Equal parts cryptography, thread-pulling, and easter eggs.
https://github.com/deepfield/public-research/blob/main/reports/2026-03-20-aisuru-ecosystem.md
#threatintel #Aisuru #kimwolf #jackskid #mossadproxy #cecilio
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.
RE: @deepfield@infosec.exchange
We dug into the binaries from a Xiongmai DVR proxyware campaign that @nicter_jp@bird.makeup wrote up. Mirai stripped for parts, PacketSDK with a dead dispatch chain, and a dormant RCE backdoor that's just... waiting.
Our report (which really is a companion piece to NICTER's): https://github.com/deepfield/public-research/blob/main/reports/2026-03-19-xiongmai-packetsdk-ipidea.md
Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.